<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CISCO ASA: Unable to connect to DMZ in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-asa-unable-to-connect-to-dmz/m-p/1228644#M835544</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mike,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried removing 'access-group ping in interface external' and the result is it will not let me ping internet (ie. google.com)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried issuing 'access-group ping in interface dmz' but still same result. I'm unable to ping from internal to dmz.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 20 May 2009 02:26:47 GMT</pubDate>
    <dc:creator>lonskinini</dc:creator>
    <dc:date>2009-05-20T02:26:47Z</dc:date>
    <item>
      <title>CISCO ASA: Unable to connect to DMZ</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-unable-to-connect-to-dmz/m-p/1228628#M835528</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have setup a network below:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;LAN &amp;lt;==&amp;gt; Cisco ASA) &amp;lt;==&amp;gt; Internet&lt;/P&gt;&lt;P&gt;             ^&lt;/P&gt;&lt;P&gt;             |&lt;/P&gt;&lt;P&gt;             DMZ&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm having problem connecting (ping) from Internal to hosts on the DMZ.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My plan is to allow all hosts on Internal to connect (ping) to DMZ. IP Address on Internal should not be natted on DMZ. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And allow some of the host to connect to Internal hosts. No natting also.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Below is my current configuration:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;=======================&lt;/P&gt;&lt;P&gt;ciscoasa(config)# sh run&lt;/P&gt;&lt;P&gt;: Saved&lt;/P&gt;&lt;P&gt;:&lt;/P&gt;&lt;P&gt;ASA Version 8.0(2)&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname ciscoasa&lt;/P&gt;&lt;P&gt;enable password Qe0yKBKYpRMBmOsL encrypted&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/0&lt;/P&gt;&lt;P&gt; nameif external&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address 116.xyz.xyz.228 255.255.255.192&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/1&lt;/P&gt;&lt;P&gt; nameif internal&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 172.31.24.253 255.255.248.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/2&lt;/P&gt;&lt;P&gt; nameif dmz&lt;/P&gt;&lt;P&gt; security-level 50&lt;/P&gt;&lt;P&gt; ip address 192.168.0.253 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/3&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt; no nameif&lt;/P&gt;&lt;P&gt; no security-level&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Management0/0&lt;/P&gt;&lt;P&gt; nameif management&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 192.168.1.1 255.255.255.0&lt;/P&gt;&lt;P&gt; management-only&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;passwd 2KFQnbNIdI.2KYOU encrypted&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;access-list ping extended permit icmp any any echo-reply&lt;/P&gt;&lt;P&gt;access-list ping extended permit icmp any any time-exceeded&lt;/P&gt;&lt;P&gt;access-list ping extended permit icmp any any unreachable&lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging asdm informational&lt;/P&gt;&lt;P&gt;mtu external 1500&lt;/P&gt;&lt;P&gt;mtu internal 1500&lt;/P&gt;&lt;P&gt;mtu management 1500&lt;/P&gt;&lt;P&gt;mtu dmz 1500&lt;/P&gt;&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;&lt;P&gt;no asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;global (external) 1 interface&lt;/P&gt;&lt;P&gt;nat (internal) 1 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;static (internal,dmz) 172.31.0.0 172.31.0.0 netmask 255.255.248.0&lt;/P&gt;&lt;P&gt;access-group ping in interface external&lt;/P&gt;&lt;P&gt;access-group ping in interface dmz&lt;/P&gt;&lt;P&gt;route external 0.0.0.0 0.0.0.0 116.xyz.xyz.193 1&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;/P&gt;&lt;P&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;/P&gt;&lt;P&gt;timeout uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;dynamic-access-policy-record DfltAccessPolicy&lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;http 192.168.1.0 255.255.255.0 management&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;/P&gt;&lt;P&gt;no crypto isakmp nat-traversal&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;dhcpd address 192.168.1.2-192.168.1.254 management&lt;/P&gt;&lt;P&gt;dhcpd enable management&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;threat-detection basic-threat&lt;/P&gt;&lt;P&gt;threat-detection statistics access-list&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt; match default-inspection-traffic&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map type inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt; parameters&lt;/P&gt;&lt;P&gt;  message-length maximum 512&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;  inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt;  inspect ftp&lt;/P&gt;&lt;P&gt;  inspect h323 h225&lt;/P&gt;&lt;P&gt;  inspect h323 ras&lt;/P&gt;&lt;P&gt;  inspect rsh&lt;/P&gt;&lt;P&gt;  inspect rtsp&lt;/P&gt;&lt;P&gt;  inspect esmtp&lt;/P&gt;&lt;P&gt;  inspect sqlnet&lt;/P&gt;&lt;P&gt;  inspect skinny&lt;/P&gt;&lt;P&gt;  inspect sunrpc&lt;/P&gt;&lt;P&gt;  inspect xdmcp&lt;/P&gt;&lt;P&gt;  inspect sip&lt;/P&gt;&lt;P&gt;  inspect netbios&lt;/P&gt;&lt;P&gt;  inspect tftp&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;prompt hostname context&lt;/P&gt;&lt;P&gt;Cryptochecksum:2f8ad3795ba88821b7fd8294ed015999&lt;/P&gt;&lt;P&gt;: end&lt;/P&gt;&lt;P&gt;====================&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry, I'm new to cisco and I am eager to learn cisco.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope you can help me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Lonski&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 15:34:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-unable-to-connect-to-dmz/m-p/1228628#M835528</guid>
      <dc:creator>lonskinini</dc:creator>
      <dc:date>2019-03-11T15:34:16Z</dc:date>
    </item>
    <item>
      <title>Re: CISCO ASA: Unable to connect to DMZ</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-unable-to-connect-to-dmz/m-p/1228629#M835529</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry, DMZ is directly connected to Cisco ASA. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 May 2009 23:55:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-unable-to-connect-to-dmz/m-p/1228629#M835529</guid>
      <dc:creator>lonskinini</dc:creator>
      <dc:date>2009-05-19T23:55:09Z</dc:date>
    </item>
    <item>
      <title>Re: CISCO ASA: Unable to connect to DMZ</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-unable-to-connect-to-dmz/m-p/1228630#M835530</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does not look like your allowing echo.  Try adding this command to your ACL..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list ping extended permit icmp any any echo&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 May 2009 23:58:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-unable-to-connect-to-dmz/m-p/1228630#M835530</guid>
      <dc:creator>mike-greene</dc:creator>
      <dc:date>2009-05-19T23:58:54Z</dc:date>
    </item>
    <item>
      <title>Re: CISCO ASA: Unable to connect to DMZ</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-unable-to-connect-to-dmz/m-p/1228631#M835531</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mike,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the advise.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have just added the acl but it still giving me same result.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there anything I should add with nat or route?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again.&lt;/P&gt;&lt;P&gt;Lonski&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 May 2009 00:12:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-unable-to-connect-to-dmz/m-p/1228631#M835531</guid>
      <dc:creator>lonskinini</dc:creator>
      <dc:date>2009-05-20T00:12:57Z</dc:date>
    </item>
    <item>
      <title>Re: CISCO ASA: Unable to connect to DMZ</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-unable-to-connect-to-dmz/m-p/1228632#M835532</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you post a show access-list.  Also can you ping the DMZ and internal hosts from the ASA?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 May 2009 00:19:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-unable-to-connect-to-dmz/m-p/1228632#M835532</guid>
      <dc:creator>mike-greene</dc:creator>
      <dc:date>2009-05-20T00:19:59Z</dc:date>
    </item>
    <item>
      <title>Re: CISCO ASA: Unable to connect to DMZ</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-unable-to-connect-to-dmz/m-p/1228633#M835533</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mike,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here it is:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ping from ASA to DMZ host (192.168.0.180)&lt;/P&gt;&lt;P&gt;--------------------&lt;/P&gt;&lt;P&gt;ciscoasa(config-if)# ping 192.168.0.180&lt;/P&gt;&lt;P&gt;Type escape sequence to abort.&lt;/P&gt;&lt;P&gt;Sending 5, 100-byte ICMP Echos to 192.168.0.180, timeout is 2 seconds:&lt;/P&gt;&lt;P&gt;!!!!!&lt;/P&gt;&lt;P&gt;Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/1 ms&lt;/P&gt;&lt;P&gt;--------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ping from ASA to Internal (172.31.26.65)&lt;/P&gt;&lt;P&gt;-------------------&lt;/P&gt;&lt;P&gt;ciscoasa(config)# ping 172.31.26.65&lt;/P&gt;&lt;P&gt;Type escape sequence to abort.&lt;/P&gt;&lt;P&gt;Sending 5, 100-byte ICMP Echos to 172.31.26.65, timeout is 2 seconds:&lt;/P&gt;&lt;P&gt;!!!!!&lt;/P&gt;&lt;P&gt;Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/1 ms&lt;/P&gt;&lt;P&gt;-------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Access-list:&lt;/P&gt;&lt;P&gt;--------------------&lt;/P&gt;&lt;P&gt;ciscoasa(config-if)# show access-list&lt;/P&gt;&lt;P&gt;access-list cached ACL log flows: total 0, denied 0 (deny-flow-max 4096)&lt;/P&gt;&lt;P&gt;            alert-interval 300&lt;/P&gt;&lt;P&gt;access-list ping; 4 elements&lt;/P&gt;&lt;P&gt;access-list ping line 1 extended permit icmp any any echo-reply (hitcnt=8) 0x6431b796&lt;/P&gt;&lt;P&gt;access-list ping line 2 extended permit icmp any any time-exceeded (hitcnt=72) 0x406ef9e9&lt;/P&gt;&lt;P&gt;access-list ping line 3 extended permit icmp any any unreachable (hitcnt=17) 0x45fe8bbe&lt;/P&gt;&lt;P&gt;access-list ping line 4 extended permit icmp any any echo (hitcnt=0) 0x931c70e&lt;/P&gt;&lt;P&gt;--------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 May 2009 00:30:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-unable-to-connect-to-dmz/m-p/1228633#M835533</guid>
      <dc:creator>lonskinini</dc:creator>
      <dc:date>2009-05-20T00:30:35Z</dc:date>
    </item>
    <item>
      <title>Re: CISCO ASA: Unable to connect to DMZ</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-unable-to-connect-to-dmz/m-p/1228634#M835534</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Your static looks like it's the wrong subnet.  Remove the current static and add this one..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (internal,dmz) 172.31.24.0 172.31.24.0 netmask 255.255.248.0&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 May 2009 00:36:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-unable-to-connect-to-dmz/m-p/1228634#M835534</guid>
      <dc:creator>mike-greene</dc:creator>
      <dc:date>2009-05-20T00:36:00Z</dc:date>
    </item>
    <item>
      <title>Re: CISCO ASA: Unable to connect to DMZ</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-unable-to-connect-to-dmz/m-p/1228635#M835535</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mike,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have replaced the static base from your suggestion but it has still same result.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By the way, this is the range of ip address of the internal:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;172.31.24.0 - 172.31.24.255&lt;/P&gt;&lt;P&gt;172.31.25.0 - 172.31.25.255&lt;/P&gt;&lt;P&gt;172.31.26.0 - 172.31.26.255&lt;/P&gt;&lt;P&gt;172.31.27.0 - 172.31.27.255&lt;/P&gt;&lt;P&gt;172.31.28.0 - 172.31.28.255&lt;/P&gt;&lt;P&gt;172.31.29.0 - 172.31.28.255&lt;/P&gt;&lt;P&gt;172.31.30.0 - 172.31.30.255&lt;/P&gt;&lt;P&gt;172.31.31.0 - 172.31.31.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 May 2009 00:58:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-unable-to-connect-to-dmz/m-p/1228635#M835535</guid>
      <dc:creator>lonskinini</dc:creator>
      <dc:date>2009-05-20T00:58:17Z</dc:date>
    </item>
    <item>
      <title>Re: CISCO ASA: Unable to connect to DMZ</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-unable-to-connect-to-dmz/m-p/1228636#M835536</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mike,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have replaced the static base from your suggestion but it has still same result.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By the way, this is the range of ip address of the internal:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;172.31.24.0 - 172.31.24.255&lt;/P&gt;&lt;P&gt;172.31.25.0 - 172.31.25.255&lt;/P&gt;&lt;P&gt;172.31.26.0 - 172.31.26.255&lt;/P&gt;&lt;P&gt;172.31.27.0 - 172.31.27.255&lt;/P&gt;&lt;P&gt;172.31.28.0 - 172.31.28.255&lt;/P&gt;&lt;P&gt;172.31.29.0 - 172.31.29.255&lt;/P&gt;&lt;P&gt;172.31.30.0 - 172.31.30.255&lt;/P&gt;&lt;P&gt;172.31.31.0 - 172.31.31.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 May 2009 00:58:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-unable-to-connect-to-dmz/m-p/1228636#M835536</guid>
      <dc:creator>lonskinini</dc:creator>
      <dc:date>2009-05-20T00:58:31Z</dc:date>
    </item>
    <item>
      <title>Re: CISCO ASA: Unable to connect to DMZ</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-unable-to-connect-to-dmz/m-p/1228637#M835537</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mike,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have replaced the static base from your suggestion but it has still same result.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By the way, this is the range of ip address of the internal:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;172.31.24.0 - 172.31.24.255&lt;/P&gt;&lt;P&gt;172.31.25.0 - 172.31.25.255&lt;/P&gt;&lt;P&gt;172.31.26.0 - 172.31.26.255&lt;/P&gt;&lt;P&gt;172.31.27.0 - 172.31.27.255&lt;/P&gt;&lt;P&gt;172.31.28.0 - 172.31.28.255&lt;/P&gt;&lt;P&gt;172.31.29.0 - 172.31.29.255&lt;/P&gt;&lt;P&gt;172.31.30.0 - 172.31.30.255&lt;/P&gt;&lt;P&gt;172.31.31.0 - 172.31.31.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 May 2009 00:58:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-unable-to-connect-to-dmz/m-p/1228637#M835537</guid>
      <dc:creator>lonskinini</dc:creator>
      <dc:date>2009-05-20T00:58:31Z</dc:date>
    </item>
    <item>
      <title>Re: CISCO ASA: Unable to connect to DMZ</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-unable-to-connect-to-dmz/m-p/1228638#M835538</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK. What is the default gateway of the machine on the internal network you were able to ping from the ASA (172.31.26.65 )?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IS the ASA the gateway for the DMZ subnet?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 May 2009 01:34:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-unable-to-connect-to-dmz/m-p/1228638#M835538</guid>
      <dc:creator>mike-greene</dc:creator>
      <dc:date>2009-05-20T01:34:44Z</dc:date>
    </item>
    <item>
      <title>Re: CISCO ASA: Unable to connect to DMZ</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-unable-to-connect-to-dmz/m-p/1228639#M835539</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The default gateway of internal host is the address of ASA on internal(172.31.24.253) and default gateway of DMZ host is also the address of ASA in DMZ (192.168.0.253).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 May 2009 01:50:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-unable-to-connect-to-dmz/m-p/1228639#M835539</guid>
      <dc:creator>lonskinini</dc:creator>
      <dc:date>2009-05-20T01:50:02Z</dc:date>
    </item>
    <item>
      <title>Re: CISCO ASA: Unable to connect to DMZ</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-unable-to-connect-to-dmz/m-p/1228640#M835540</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just to add:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can ping from DMZ host the address of the DMZ gateway (192.168.0.253)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 May 2009 01:54:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-unable-to-connect-to-dmz/m-p/1228640#M835540</guid>
      <dc:creator>lonskinini</dc:creator>
      <dc:date>2009-05-20T01:54:24Z</dc:date>
    </item>
    <item>
      <title>Re: CISCO ASA: Unable to connect to DMZ</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-unable-to-connect-to-dmz/m-p/1228641#M835541</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you issue a clear xlate and try and ping again? Can you also post the running config again.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 May 2009 02:06:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-unable-to-connect-to-dmz/m-p/1228641#M835541</guid>
      <dc:creator>mike-greene</dc:creator>
      <dc:date>2009-05-20T02:06:19Z</dc:date>
    </item>
    <item>
      <title>Re: CISCO ASA: Unable to connect to DMZ</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-unable-to-connect-to-dmz/m-p/1228642#M835542</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Done clearing xlate... same result &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here's the updated config:&lt;/P&gt;&lt;P&gt;----------------&lt;/P&gt;&lt;P&gt;ciscoasa(config)# sh run&lt;/P&gt;&lt;P&gt;: Saved&lt;/P&gt;&lt;P&gt;:&lt;/P&gt;&lt;P&gt;ASA Version 8.0(2)&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname ciscoasa&lt;/P&gt;&lt;P&gt;enable password Qe0yKBKYpRMBmOsL encrypted&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/0&lt;/P&gt;&lt;P&gt; nameif external&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address 116.xyz.xyz.228 255.255.255.192&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/1&lt;/P&gt;&lt;P&gt; nameif internal&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 172.31.24.253 255.255.248.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/2&lt;/P&gt;&lt;P&gt; nameif dmz&lt;/P&gt;&lt;P&gt; security-level 50&lt;/P&gt;&lt;P&gt; ip address 192.168.0.253 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/3&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt; no nameif&lt;/P&gt;&lt;P&gt; no security-level&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Management0/0&lt;/P&gt;&lt;P&gt; nameif management&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 192.168.1.1 255.255.255.0&lt;/P&gt;&lt;P&gt; management-only&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;passwd 2KFQnbNIdI.2KYOU encrypted&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;access-list ping extended permit icmp any any echo-reply&lt;/P&gt;&lt;P&gt;access-list ping extended permit icmp any any time-exceeded&lt;/P&gt;&lt;P&gt;access-list ping extended permit icmp any any unreachable&lt;/P&gt;&lt;P&gt;access-list ping extended permit icmp any any echo&lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging asdm informational&lt;/P&gt;&lt;P&gt;mtu external 1500&lt;/P&gt;&lt;P&gt;mtu internal 1500&lt;/P&gt;&lt;P&gt;mtu management 1500&lt;/P&gt;&lt;P&gt;mtu dmz 1500&lt;/P&gt;&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;&lt;P&gt;no asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;global (external) 1 interface&lt;/P&gt;&lt;P&gt;nat (internal) 1 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;static (internal,dmz) 172.31.24.0 172.31.24.0 netmask 255.255.248.0&lt;/P&gt;&lt;P&gt;access-group ping in interface external&lt;/P&gt;&lt;P&gt;access-group ping in interface dmz&lt;/P&gt;&lt;P&gt;route external 0.0.0.0 0.0.0.0 116.xyz.xyz.193 1&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;/P&gt;&lt;P&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;/P&gt;&lt;P&gt;timeout uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;dynamic-access-policy-record DfltAccessPolicy&lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;http 192.168.1.0 255.255.255.0 management&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;/P&gt;&lt;P&gt;no crypto isakmp nat-traversal&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;dhcpd address 192.168.1.2-192.168.1.254 management&lt;/P&gt;&lt;P&gt;dhcpd enable management&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;threat-detection basic-threat&lt;/P&gt;&lt;P&gt;threat-detection statistics access-list&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt; match default-inspection-traffic&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map type inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt; parameters&lt;/P&gt;&lt;P&gt;  message-length maximum 512&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;  inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt;  inspect ftp&lt;/P&gt;&lt;P&gt;  inspect h323 h225&lt;/P&gt;&lt;P&gt;  inspect h323 ras&lt;/P&gt;&lt;P&gt;  inspect rsh&lt;/P&gt;&lt;P&gt;  inspect rtsp&lt;/P&gt;&lt;P&gt;  inspect esmtp&lt;/P&gt;&lt;P&gt;  inspect sqlnet&lt;/P&gt;&lt;P&gt;  inspect skinny&lt;/P&gt;&lt;P&gt;  inspect sunrpc&lt;/P&gt;&lt;P&gt;  inspect xdmcp&lt;/P&gt;&lt;P&gt;  inspect sip&lt;/P&gt;&lt;P&gt;  inspect netbios&lt;/P&gt;&lt;P&gt;  inspect tftp&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;prompt hostname context&lt;/P&gt;&lt;P&gt;Cryptochecksum:2f8ad3795ba88821b7fd8294ed015999&lt;/P&gt;&lt;P&gt;: end&lt;/P&gt;&lt;P&gt;--------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 May 2009 02:12:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-unable-to-connect-to-dmz/m-p/1228642#M835542</guid>
      <dc:creator>lonskinini</dc:creator>
      <dc:date>2009-05-20T02:12:13Z</dc:date>
    </item>
    <item>
      <title>Re: CISCO ASA: Unable to connect to DMZ</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-unable-to-connect-to-dmz/m-p/1228643#M835543</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Remove the ping ACL from the external interface and apply it to the dmz interface and try again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no access-group ping in interface external&lt;/P&gt;&lt;P&gt;access-group ping in interface dmz&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 May 2009 02:15:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-unable-to-connect-to-dmz/m-p/1228643#M835543</guid>
      <dc:creator>mike-greene</dc:creator>
      <dc:date>2009-05-20T02:15:31Z</dc:date>
    </item>
    <item>
      <title>Re: CISCO ASA: Unable to connect to DMZ</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-unable-to-connect-to-dmz/m-p/1228644#M835544</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mike,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried removing 'access-group ping in interface external' and the result is it will not let me ping internet (ie. google.com)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried issuing 'access-group ping in interface dmz' but still same result. I'm unable to ping from internal to dmz.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 May 2009 02:26:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-unable-to-connect-to-dmz/m-p/1228644#M835544</guid>
      <dc:creator>lonskinini</dc:creator>
      <dc:date>2009-05-20T02:26:47Z</dc:date>
    </item>
    <item>
      <title>Re: CISCO ASA: Unable to connect to DMZ</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-unable-to-connect-to-dmz/m-p/1228645#M835545</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry, it's already on your DMZ interface.  Forget my last post.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 May 2009 02:27:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-unable-to-connect-to-dmz/m-p/1228645#M835545</guid>
      <dc:creator>mike-greene</dc:creator>
      <dc:date>2009-05-20T02:27:42Z</dc:date>
    </item>
    <item>
      <title>Re: CISCO ASA: Unable to connect to DMZ</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-unable-to-connect-to-dmz/m-p/1228646#M835546</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can remove this command..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list ping extended permit icmp any any echo&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Other then that the config looks ok to me. ... It is late though and it's been a long day.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only other item I can think of to check tonight is the routing tables on the internal and DMZ systems to make sure there not sending the traffic somewhere else.. I believe the command is route print on a Microsoft box.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 May 2009 02:54:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-unable-to-connect-to-dmz/m-p/1228646#M835546</guid>
      <dc:creator>mike-greene</dc:creator>
      <dc:date>2009-05-20T02:54:44Z</dc:date>
    </item>
    <item>
      <title>Re: CISCO ASA: Unable to connect to DMZ</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-unable-to-connect-to-dmz/m-p/1228647#M835547</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mike,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yeah, it's been a long day.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just a thought, do we need to change from static to dynamic nat?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm not sure, I'm thinking that internal is unable to communicate with dmz because it is from different subnet since we used the static nat. ??? not so sure. &lt;span class="lia-unicode-emoji" title=":grinning_face_with_big_eyes:"&gt;😃&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 May 2009 03:54:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-unable-to-connect-to-dmz/m-p/1228647#M835547</guid>
      <dc:creator>lonskinini</dc:creator>
      <dc:date>2009-05-20T03:54:32Z</dc:date>
    </item>
  </channel>
</rss>

